More jobs:
Senior Director Cybersecurity Operations and Risk
Remote / Online - Candidates ideally in
Providence, Providence County, Rhode Island, 02912, USA
Listed on 2026-05-11
Providence, Providence County, Rhode Island, 02912, USA
Listing for:
United Natural Foods, Inc.
Remote/Work from Home
position Listed on 2026-05-11
Job specializations:
-
IT/Tech
Cybersecurity, Security Manager
Job Description & How to Apply Below
Job Overview
The Senior Director of Security Operations and Risk leads the defensive security strategy and operational execution responsible for strategic oversight, operational excellence, and continuous maturity of the security operations center (SOC) Vulnerability Management (VM), and Governance, Risk, and Compliance (GRC).
Core Responsibilities- Develop and implement a multi-year roadmap for Defensive Security that aligns Sec Ops, Vulnerability Management, and GRC objectives with the organization's corporate risk priorities, security architecture, and evolving business needs.
- Act as the main point of contact for defensive security metrics, delivering clear, data-driven insights on threat of resilience and residual risk to the CISO and executive leadership.
- Oversee the lifecycle of security policies and standards, ensuring compliance, technical enforce ability, and practicality for the business. Ensure that streamlined processes and comprehensive runbooks are established.
- Direct 24/7 SOC operations to deliver best-in-class monitoring, advanced threat detection, proactive analysis, dynamic threat hunting, and rapid incident response.
- Manage escalations of anomalous activities, vulnerabilities, and major cyber events by ensuring swift triage, coordinated response efforts, and consistent alignment with goals.
- Advance protection and detection capabilities by leveraging cutting-edge analytics, automation, innovative engineering, and recognized cybersecurity architectural best practices.
- Create an inclusive, high-performance environment that supports continuous learning and career development for security analysts, engineers, and risk professionals.
- Implement retention and succession plans to address the pressures and burnout risks common in high-tempo defensive operations.
- Foster a culture of transparency and accountability, empowering team members to proactively identify and address systemic security weaknesses.
- Direct proactive threat hunting, red-team simulations, and tabletop exercises to validate incident response readiness and uncover hidden architectural gaps.
- Maintain continuous audit readiness by automating compliance evidence collection to support seamless internal and external reviews without unexpected issues.
- Inspire high-performing teams and cultivate workforce excellence.
- Performs other duties as assigned.
- Bachelor’s degree in computer science, information systems or related field.
- At least 1 industry recognized data, compliance, and/or cybersecurity certification.
- 12+ years in cybersecurity with a focus in security operations, monitoring, detection, investigation, and threat intelligence.
- 5+ years in a leadership position overseeing and leading a security operations program.
- More than 5 years of hands‑on experience with risk management frameworks (such as NIST CSF, ISO 27001, and FAIR), with a focus on data‑driven risk beyond basic compliance.
- Experience in managing complex third‑party relationships, including auditing service provider performance against SLAs and ensuring high‑fidelity alerting.
- Experience in leading a team, identifying skill gaps and creating career paths.
- Demonstrated success leading enterprise‑wide vulnerability management programs, emphasizing risk‑based prioritization and cross‑departmental remediation workflows.
- Proven incident commander experience, with the ability to lead high‑pressure response efforts and clearly communicate impact to executive leadership and legal counsel.
- Incident Orchestration & Resilience:
Experience leading strategic responses to high‑impact security events, prioritizing business continuity and long‑term remediation. - Strategic Security Governance:
Expertise in scaling Governance, Risk, and Compliance (GRC) frameworks across business units to address changing regulatory and industry standards. - Next‑Generation Architecture:
In‑depth knowledge of Zero Trust and SASE frameworks, with a focus on replacing legacy VPN environments. - Emerging Tech Governance:
Understanding of risks and security requirements for agentic AI workflows and autonomous entities. - Executive Risk Communication:
…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×